Dire Wolf Ransomware Comes Out Snarling, Bites Technology, Manufacturing
ID: 9efb9195-d10e-5feb-ac1b-ee2b2dfd0a4d
STIX ID: report--9efb9195-d10e-5feb-ac1b-ee2b2dfd0a4d
Feed Name: Dark Reading
Date Published: 2025-06-25
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trustwave SpiderLabs analyzed a newly emergent ransomware group dubbed "Dire Wolf" that has impacted 16 organizations across 11 countries; the actor uses double extortion with targeted, victim-tailored encryptors and a monthlong payment window, publishes proof-of-exfiltration on a leak site, and provides live-chat credentials to negotiate ransoms. The sample analyzed was a UPX-packed Golang binary that enforces a single-instance mutex (Global\direwolfAppMutex), disables Windows event logging and recovery features, terminates interfering processes/services, and encrypts files using Curve25519 and ChaCha20 while appending a .direwolf extension; defenders are advised to harden endpoints, patch critical vulnerabilities, and deploy detections for the observed defense-evasion and impact techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
